Junglewise Threat Intelligence

CVE-2024-40624: TorrentPier insecure deserialization in get_tracks function

CVE-2024-40624 · Severity: critical · CVSS 9.8 · Published 2024-07-15

Technologies: TorrentPier, torrentpier/torrentpier (Packagist). Vendors: TorrentPier, Packagist.

Executive brief

TorrentPier is an open-source BitTorrent tracker engine. A security vulnerability in how the software handles browser cookies allows an attacker to execute malicious code on the server. This could lead to a complete takeover of the website, theft of user data, or disruption of service.

Technical details

A deserialization of untrusted data vulnerability exists in TorrentPier versions 2.4.3 and earlier. The `get_tracks()` function in `library/includes/functions.php` uses the native PHP `unserialize()` function on the contents of the `bb_t` cookie without proper validation. An unauthenticated remote attacker can exploit this by providing a specially crafted cookie containing a PHP gadget chain (such as Guzzle/FW1). Successful exploitation allows the attacker to perform arbitrary file writes and execute arbitrary PHP code on the underlying server. The issue is addressed in version 2.4.4.

Affected products

  • TorrentPier TorrentPier <= 2.4.3

Timeline

  • 2024-07-13: disclosed
  • 2024-07-15: advisory: GHSA-fg86-4c2r-7wxw published
  • 2024-07-15: patched

References

Related threats